| name | sq-gomod-dependabot |
| description | Reviews and merges Dependabot pull requests for Go modules (gomod) at the sq repo root. Use for dependabot gomod PRs, go.mod/go.sum updates, and Go module security bumps—not site/ Bun PRs. |
| license | MIT |
| compatibility | Requires gh CLI (authenticated), Go toolchain, make test-short, and network access to GitHub. |
| metadata | {"author":"Todd Papaioannou","homepage":"https://sq.io","version":"0.2.1"} |
sq-gomod-dependabot
Maintainer workflow for Dependabot PRs updating go.mod /
go.sum at the repository root. For site/
Bun/Hugo PRs, use sq-site-dependabot; for
GitHub Actions pins under .github/workflows/, use
sq-actions-dependabot.
No bun.lock sequencing — multiple gomod PRs are less coupled than site PRs,
but still prefer merging after CI is green.
Operating modes
| Mode | Actions | Merge |
|---|
| Audit | List/classify; direct vs indirect | No |
| Validate | Diff review; make test-short | No |
| Full | Validate + merge with consent | Per PR |
Default to Audit unless the user asks to merge.
Phase 0 — Tool bootstrap
command -v gh >/dev/null && gh auth status
command -v go >/dev/null && go version
Phase 1 — Discovery
From repository root:
gh pr list --author 'app/dependabot' --state open \
--json number,title,headRefName,mergeable,statusCheckRollup \
--jq '.[] | select(.headRefName | test("^dependabot/")) | select(.title | test("go|gomod|golang"; "i"))'
The title filter matches go/golang, so it also catches GitHub Actions PRs
like goreleaser-action or golangci-lint-action. Those touch only
.github/workflows/, not go.mod; hand them to
sq-actions-dependabot. Confirm the PR does
not only touch site/ (gh pr diff <n> --name-only); if it touches both,
split judgment: site hunks → sq-site-dependabot.
Phase 2 — Risk
| Level | Examples | Action |
|---|
| Low | Patch indirect, test-only modules | Merge after CI |
| Medium | Direct minor/patch runtime dep | Notes + test-short |
| High | Major, replace, breaking sec | Hold; full review |
Phase 3 — Validate
On PR branch:
make test-short
Review go mod why / diff for unexpected indirect churn.
Phase 4 — Merge (consent-gated)
After required checks pass:
gh pr merge <n> --squash --delete-branch
Use --admin only when the user explicitly requests and checks are green.
Verdict template
## Dependabot gomod PR #NNN — <module>
- **Direct/indirect:** …
- **CI:** pass / fail
- **make test-short:** pass / fail
- **Verdict:** merge | hold
See AGENTS.md.